Spring Boot Actuator AutoConfigure
88%
Total Score
healthy
Healthy release from an actively maintained, well-backed project, with only milestone status and workflow hygiene concerns.
This is a milestone prerelease rather than a final release, so it carries more compatibility risk despite being part of a stable major line.
All 10 workflows were analyzed, use read-only permissions, and have no untrusted checkout or script-injection findings. Three of 28 action references are unpinned, and high-confidence template-injection findings remain workflow hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10582 spring-boot-actuator-autoconfigure is vulnerable to Authentication Bypass in versions 4.0.0 - 4.0.5. | 4.0.0 - 4.0.5 | Critical |
CVE-2023-20873 org.springframework.boot:spring-boot-actuator-autoconfigure is vulnerable to Security Vulnerability in versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.15 and 0.0.0 - 2.5.15. | 0.0.0 - 2.5.152.6.0 - 2.6.152.7.0 - 2.7.11 +1 more | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.boot:spring-boot-autoconfigure Version 4.2.0-M2 | — | — |
org.springframework.boot:spring-boot-actuator Version 4.2.0-M2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.